Sophos X-Ops reported that a threat actor built and tested an AI-assisted post-exploitation framework designed to evade endpoint detection and response tools, using a mix of malicious files, Cobalt Strike profiles, Python shellcode-injection scripts, a Telegram Bot API command-and-control channel, and a Cloudflare Worker redirector. Investigators found a supporting Git repository that automated Active Directory discovery and maintained a malware-testing lab with multiple virtual machines to evaluate bypass techniques against Sophos, CrowdStrike, and Microsoft Defender environments; many scripts appeared partly AI-generated and included Russian-language elements.
The framework used a Python payload generator to create Rust- and Go-based payloads with encryption, evasion, and alternate execution methods, ultimately producing nearly 80 modules that tested more than 70 techniques. Sophos said the operators used tools including Cursor, Claude Opus 4.5, and Model Context Protocol to coordinate workflows, ingest public research, and map activity to MITRE ATT&CK, but found no clear evidence that AI independently invented new malware capabilities; the company also linked the development activity to known ransomware deployment and data-theft operations and urged organizations to maintain layered defenses including patching, MFA, passkeys, and strong EDR coverage.

Get the actors, campaigns, and ATT&CK mapping behind it.
1 event from the most recent confirmed update back to the earliest known activity.
Sophos X-Ops reported on a threat actor that used AI-assisted tooling, including Cursor, Claude Opus 4.5, and Model Context Protocol, to develop and test EDR evasion techniques within a post-exploitation framework. The investigation linked the development activity to known ransomware deployment and data theft operations and documented supporting infrastructure such as Telegram Bot API C2, a Cloudflare Worker redirector, and malware-testing lab environments.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
7 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecybersecuritynews.com
Open sourcedarkreading.com
Open sourcesophos.com
Open sourcebleepingcomputer.com
Open sourcehelpnetsecurity.com
Open sourcesophos.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.